hijack by www.3721.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by restfullone, Feb 16, 2005.

  1. restfullone

    restfullone Private E-2

    My browser has been taken over by 3721 and has put a chinese keyword
    function on my browse,this stops me from english sites.As i don't understand chinese its no use to me,so can someone please help me.I have used there turn of but its still there,even blocked it but it still stays there.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. restfullone

    restfullone Private E-2

    I have been into 3721 sites found there email address and sent them 3 emails but they all come back saying can't deliver,have used there feedback but won't go ie comes up error not found.I have on my pc microsoft anti spyware
    beta 1,spy blaster,cwshredder,kingsoft anti virus-duba6 andpfw6 and last avg7.So i have tryed all of them blocking 3721 or removing but its still on my pc. The beta 1 tells me thats its threat level:severe,author :Inter China Network Software Co Ltd.The path:c:\windows\downlor\cnshook.dll Versio
    1.0.2.3
    Technical Details CLSID:{D157330A-9EF3-49F8-9A67-414AC41ADD43}
    Prog ID:CnsMinHK.CnsHook.1 Original File Name MD5
    c1F1c1654955ab92431balba8728Fe29.
    I will run my beta after this and try again but might stop it today but it back next time i open my pc even when you block it and beta tells me its bloked by a pop up screen bottom left.So whats my next step?.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sending emails like that is a very bad idea. Clicking on their feedback links is also a bad idea. All you did was confirm that your IP and email addresses are valid so they can get you on more lists. Never ever click a reply button or a remove me from your list like this. It is the worst thing you can do.

    Your next step is to do what all of what I gave you in my first message. I see no information in your message that you did any of it. And if you had complete all the cleaning steps and still had a problem, I asked you to follow the guidelines given and to post a HijackThis log.
     
  5. restfullone

    restfullone Private E-2

    Well in the end my let me download HijackThis 1.99,well it took three times but i got there now.I ran this and found problems in02-04-08-09 checked all items to clear but 2 came back and would not clear,eventryed 5 times but would not move. ON one scan the number 8 came back as well. so i did a reboot to see what came back wekk i got the lot back.So must be in the start setup but i blocked that on my spyware today which i ran 3 times and its telling i have a clear system but if i recheck there back and it wont send a copy to microsoft beta 1.So whats my next step? I must say my pc is faster after this clean up.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! This is the third request for the same thing.

    Please do what I asked. Download HijackThis Version 1.99.1 from the link I gave you and follow the directions below too and post your log as an attachment to a message.

    By the way I have no idea what you last message why trying to say.
     
  7. restfullone

    restfullone Private E-2

    I have Hijackthis 1.99 and run it,found the threads of 3721 removed them all once but they reload them self well 3 do.So did a reboot to see what came up and they reload on auto at startup.The last message are numbers from the program spec and its info.So it looks as i need to go into startup and wipe out 3721 from there.So now i go hunting the keys in startup menu.Sorry about my last message some times my dyslexia comes in.Well i am only (another brick in the wall) .pink floyd
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    restfullone,

    You still did not post your log as Chaslang requested. In order to best assist you we need to view the logs we request. Please attach a current HJT log as an attachment to your post and Chas will check it when time permits.:)
     
  9. restfullone

    restfullone Private E-2

    I have found this info on CnsMin its a keyword lockup provider that takes over the search features of IE's address bar.Its aimed at providing keywords using chinese characters and is extremely anty social methods make it difficult to uninstall.I have now found the uninstalling info of this program at
    www.intermute.com under {C} setion.It seems that i am not the only one to get this problem,so now i can set about removing this from my pc.I would like to thank you all for your support and time.I hope the info i found helps someone remove there software,when they get the same problem
     
  10. SarifanlordX

    SarifanlordX Private E-2

    Well Honestly all I saw was you talking to you're self (Sorry but it's true)

    Should follow the instructions Chas and bj has given you to further insure you are clear from any other nasty things. :rolleyes:
     
  11. restfullone

    restfullone Private E-2

    If you look at my message and read it you would see that i download HijackThis 1.99 in two posts but could not past as my browser has chinese in 90% of my pc.So i found by chance a place that info that was some use to me and might help someone with the same problem. So i wont come back if thats the way you feel.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Go ahead and paste the log here and Chaslang will convert it to an attachment for you.
     
  13. restfullone

    restfullone Private E-2

    I have found some one who reads chinese and have sent a copy of the lod.
     

    Attached Files:

  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Good Job! Chaslang will check your log and post you a fix when time permits. Hang in there :)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it took long enough to get to this point. But you still have HijackThis running from the wrong folder:
    C:\Documents and Settings\user\ja\HijackThis.exe

    You should move this to C:\Program Files\HJT as we requested.

    But let's continue!

    Is the below KAV6 an antivirus package.
    C:\KAV6\KWatchUI.EXE
    C:\KAV6\MailMon.EXE
    C:\KAV6\KAVPlus.EXE

    If so you must install either it or AVG. You must not use more than one AV package!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Mar 6, 2005
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also have this:

    CnsMin

    The information below provides details about this pest.

    Summary

    Hijacks the search feature in IE, replacing your typed search strings with Chinese characters and taking you to a Chinese search site. These functions are likely of value to many Chinese users, but are not appreciated by others. On June 7, 2004 PestPatrol researched CnsMin and at that time removal was nearly impossible and the uninstaller which was included removed most components, but left the machine with no network or Internet connection. In 6 out of 6 boots after installing CnsMin, our machine crashed within 5 minutes. CnsMin was intended to be a search support tool for users, but its operation in our test machines suggests that the current version, when run in an English computer, should be classified as a Nuker. CPR again researched CnsMin July 9, 2004 and the results were nearly the same as above except no uninstalled was provided. In addition, numerous popup ads were displayed which were difficult to close.

    The above is quoted from: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453072511
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After uninstalling Kingsoft, do the following:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
    O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
    O8 - Extra context menu item: !ËÑÒ»ËÑ - res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\downlo~1\CnsHook.dll
    C:\WINDOWS\downlo~1\CnsMin.dll
    C:\WINDOWS\downlo~1\CnsMinEx.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. I have a feeling that the above downlo~1 folder is really Downloaded Program Files If that is true you will need to do the below to find and delete these files:

    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s CnsHook.dll

    del CnsHook.dll
    attrib -r -h -s CnsMin.dll
    del CnsMin.dll
    attrib -r -h -s CnsMinEx.dll
    del CnsMinEx.dll
    exit

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  19. restfullone

    restfullone Private E-2

    Well i have removed the three you wanted and then did a re boot.Then went onto Ie to clear but found in the history some 25 lines,all from3721 cleaned them out,then it started to ask to reload 3721 time after time which i blocked with spy bot.I went into start and run under cmd and it came up in chinese,so i now need to get some one to help me with this and yes i can't read chinese at all.So this gives me some problems. I looked on your lead and found that many have this problem with CnsMin and they all say its a sod to remove.So when i find some one to help sort it out i contact you after that.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall Kingsoft Antivirus as I suggested?

    Also you should have posted the follow up HJT log I requested.
     
  21. Bypass

    Bypass Private E-2

    Follow this procedure to remove 3721

    3721 is something hated and damned by everyone excluding 3721 itself.

    1. Restart the computer, enter safe mode.
    2. Run regedit, navigate to:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    and then remove the key "CnsMin" at right-side panel.
    3. Migrate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\AdvancedOptions and then delete the entire "!CNS" directory.
    4. Migrate to HKEY_LOCAL_MACHINE\SOFTWARE\3721 and HKEY_CURRENT_USER\Software\3721. Remove BOTH directories.
    5. Migrate to HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main, and delete the keys starting with CNS such as CNSEnable.
    6. Find files that have 3721, CnsMin, cnsio in their names. They are likely the files used by 3721. Delete them.

    -- A 3721 hunter from China
     
  22. Bypass

    Bypass Private E-2

    Re: Follow this procedure to remove 3721

    3721 is a rougue company. 3721 can control your computer; if it doesn't allow you to visit a website, you simply won't be able to. Thus many big sites are not brave enough to fight 3721, as it is hidden in over 90% of computers in China. Microsoft even has PARTNERSHIP with it (try http://china.msn.com/). Those MFs!!!

    This software can clean up 3721: http://www.noadware.net/noadware.exe

    If you can find someone who knows Chinese, this software can do the job better (it specializes in cleaning up 3721):

    http://ftp.pconline.com.cn/pub/download/200409/ban3721.rar
     
  23. restfullone

    restfullone Private E-2

    I now don't have 3721 on my pc,when trying to remove it it crashed the lot and could not get in,so had a clean install.So thanks for your help and hope some one has better luck than me on this problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds